Adding a Remote Node Record to the Parameter File Manually for the SSL or TLS Protocol

About this task

Refer to the Remote Node Security Feature Definition Worksheet that you created for the remote node you are adding when you complete this procedure. The following procedure assumes that this remote node uses the SSL or TLS protocol and client authentication with Connect:Direct® Secure Plus unless you want to override the IBM Connect:Direct Secure Plus parameter settings from the PROCESS statement. For more information, see Override Settings in IBM Connect:Direct Processes.

To add a remote node record manually for the SSL or TLS protocol:

Procedure

  1. On the Option line type I (Insert Node) on the Secure+ Admin Tool Main Screen and press Enter to add a node. The Secure+ Create/Update Panel displays.
    File  Edit  Help                                                                                      
    -------------------------------------------------------------------------------                         
                        Secure+ Admin Tool: Main Screen                Row 1 of 1                         
    Option ===>                                                        Scroll CSR                           
                                                                                                                                      
    Table Line Commands are:                                                       
                                                                                                                                      
     U Update node           H View History          D  Delete node                                         
     I Insert node           V View node             CL Clone node                                          
                                                                                                                                      
     Node Filter : *                                                                                        
                                                                                                                                      
     Secure+                      External Client                                  
     LC Node Name         Type Protocol Override Encryption   Auth    Auth                                   
     -- ----------------  ---- -------- -------- ---------- -------- --------                                
     I MY_LOCAL           L   TLSV13       Y         Y         N       Y                                    
     ******************************* BOTTOM OF DATA ********************************                                
  2. On the Secure+ Create/Update Panel:
    1. In the Node Name field, type the name for the remote node that corresponds to its name in the network map.
    2. Type R in the Type (Local or Remote) field.
      CMD                    Secure+ Create/Update Panel                             
      
       Option ===>                                                                    
      
       
      
       Node Name:   MY.REMOTE            Type:  R       (Local or Remote)
      
       --------------------------------------------------------------------------
      
      | Security Options     |  EA Parameters        |  SSL/TLS Parameters       |
      
      | ---                     --                      ---                      |
      
       --------------------------------------------------------------------------
      
       Secure+ Protocol:                Security Mode  (Yes   No   Default to Local)  
      
        Enable SSL           D           Enable FIPS                       
      
        Enable TLS 1.0       D           Enable SP800-131a Transition    D
      
        Enable TLS 1.1       D           Enable SP800-131a Strict        D
      
        Enable TLS 1.2       D           Enable NSA Suite B 128 bit      D
      
        Enable TLS 1.3       D           Enable NSA Suite B 192 bit      D
      
       
      
       Auth Timeout:         120        Enable Override                  D
      
       
      
       Alias  Names:                    TCP Information:  
      
                                         IPaddr:                 
      
                                         Port:         
      
                        
      
       
      
                                                            OK        Cancel  
  3. SSL being an older protocol is no more available for selection from Connect:Direct version 6.3. To implement SSL with version 6.2 and below, do one of the following, depending on whether you want to use SSL for all data Transfers or on a Process-by-Process basis:
    1. Type Y beside the Enable SSL field to enable the SSL protocol for this remote node.
    2. Type N beside the Enable SSL field to disable the SSL protocol.
    Note: SSL cannot be enabled for version 6.3 of Connect:Direct. Once disabled while updating the Secure Plus Parameter File, SSL cannot be enabled again.
  4. TLS 1.0 and TLS 1.1 are no more available for selection from Connect:Direct version 6.3. To implement TLS 1.2, do one of the following, depending on whether you want to use TLS for all the data transfers or on a Process-by-Process basis:
    1. Type Y beside the Enable TLS 1.2 field to enable the TLS protocol for this remote node. Repeat for TLS 1.3.
    2. Type N beside the Enable TLS 1.2 field to disable the TLS 1.2 protocol.
      Note: TLS 1.0 and TLS 1.1 cannot be enabled for version 6.3 of Connect:Direct. Once disabled while updating the Secure Plus Parameter File, these protocols cannot be enabled again.
  5. In the Security Mode field, type Y, N, or D to enable or disable
    multiple protocols
    such as, FIPS, SP800-131a and NSA Suite B.
  6. Alias Names field do not apply to remote node. This field should be left blank.
  7. TCP Information fields (IP addr and Port) do not apply to remote node. This field should be left blank.
  8. Depending on whether you want to use the Connect:Direct Secure Plus parameter settings override feature, type Y to enable or N to disable beside the Override field. Enabling Override for the Remote record allows not only the Process to override the security settings but also allows the SNODE to override the security setting. Use caution when enabling this option on the Remote record to override any setting defined in the Local node record
    .
  9. Select the SSL/TLS parameters panel by typing SSL and press Enter to display the Secure+ Create/Update panel:
    CMD                    Secure+ Create/Update Panel             
    Option ===>                                                                    
    
    Node Name:   CD.ZOS.USER2         Type:  R       (Local or Remote) 
    --------------------------------------------------------------------------
     Security Options     |  EA Parameters        |  SSL/TLS Parameters       |
     ---                     --                      ---                      |
    --------------------------------------------------------------------------
    
    Enable Client Auth            N                 (Yes   No   Default to Local)  
    Enable Data Encrypt           D                 (Ignored  Forced to Y)
    Cipher Selection Method       MANUAL            (Extended  Manual)
    
                                   ------------------------------------------- 
       Certificate Label          | *                                         | 
           Cipher Suites          | FFFF                                      | 
    Certificate Pathname          | *                                         | 
    Certificate Common Name       |                                           | 
                                   ------------------------------------------- 
    
    
                                                         OK        Cancel    
                                                         --        ---
    
  10. To implement Client Authentication, type Y for enable or N to disable beside the Client Auth. Since, Data Encryption field (Enable Data Encrypt) has been deprecated from release 6.2, it will not be effective on process though user can change it in secure parmfile. It always will work as Enable.
  11. Select Certificate Label field by placing the cursor on the text and press Enter. On the entry panel specify the Certificate Label as defined in the certificate or leave blank to use the default certificate defined in the key database or key ring. Leaving the certificate label blank will generate a warning message up on saving the parameter file. This is meant as a warning that the key store must define a default certificate. Select the Certificate Label field and press Enter.
    Note: The Certificate label field is automatically set to '*' (Default to Local) in the Remote Node record. You are not allowed to update this field for a remote node.
  12. Certificate Pathname does not apply to a remote node. This field should be left blank
  13. Select Cipher Suites by placing the cursor on the text and press Enter.

    Extended or Manual cipher suite selection panel will open according to Cipher selection method field.

    1. Manual Panel:
      1. To select ciphers, order the list in All Available Cipher-Suites by placing them 1 through n (maximum of 10).
      2. As ciphers are selected they move to the Enabled Cipher-Suites on the right side. This list is the default cipher list.

        This is a scrollable panel so use the F8 key to more forward and F7 to move back.

      Option --->
      
            Cipher Filtering:Protocol         Cipher Sorting:Strongest
      
            Update the order field below to enable and order Cipher Suites
      
        O   All Available Cipher Suites          Enabled Cipher Suites
       ==   ==================================== ====================================
                                                                          More:     +
       1   TLS_AES_256_GCM_SHA384                TLS_AES_256_GCM_SHA384
       2   TLS_AES_128_GCM_SHA256                TLS_AES_128_GCM_SHA256
       3   TLS_ECDHE_ECDSA_W_AES_256_GCM_SHA384  TLS_ECDHE_ECDSA_W_AES_256_GCM_SHA384
       4   TLS_ECDHE_ECDSA_W_AES_256_CBC_SHA384  TLS_ECDHE_ECDSA_W_AES_256_CBC_SHA384
           TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
           TLS_ECDHE_ECDSA_W_AES_128_CBC_SHA256
           TLS_ECDHE_ECDSA_W_AES_128_GCM_SHA256
           TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
           TLS_ECDHE_ECDSA_WITH_RC4_128_SHA
           TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA
           TLS_ECDHE_ECDSA_WITH_NULL_SHA
           TLS_ECDHE_RSA_WIT_AES_256_GCM_SHA384
           TLS_ECDHE_RSA_WIT_AES_256_CBC_SHA384
           TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
           TLS_ECDHE_RSA_WIT_AES_128_GCM_SHA256
           TLS_ECDHE_RSA_WIT_AES_128_CBC_SHA256
           TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
           TLS_ECDHE_RSA_WITH_RC4_128_SHA
    2. Extended panel:
      Node Name:
      Displays the node name being updated.
      (L/R):
      Indicates whether the node is Local (L) or Remote (R).
      Panel Name:
      "Secure + Extended Cipher Suite" is the name for panel DGA@P141.
      Selection and Filtration Display:
      Displays the number of selected ciphers, the number passing filtration, and the total number available.
      Selection:
      These options are used to select the ciphers by protocol. A selected cipher is pink and has a number in the ‘O’ column. There are 3 fields available, and for each field the valid values are 1-99 and ALL:
      ANY:
      Allows the selection of cipher suites for any protocol, either a maximum number, or all that are available.
      TLS12:
      Allows the selection of cipher suites that are supported by TLS12, either a maximum number, or all that are available. This field will be enabled if either the Cipher Filtering field is set to None (N) or if the TLS12 protocol is enabled on panel DMADP126 (Secure+ Create/Update Panel). Otherwise it will be disabled.
      TLS13:
      Allows the selection of cipher suites that are supported by TLS13, either a maximum number, or all that are available. This field will be enabled if either the Cipher Filtering field is set to None (N) or if the TLS13 protocol is enabled on panel DMADP126 (Secure+ Create/Update Panel). Otherwise it will be disabled.
      Note: If all of the above Selection fields are blank, then the cipher suites are selected manually by numbering them 1-n (maximum of 99).
      Note: If any of the above Selection fields are not blank, then all the cipher suites for that field are automatically selected and numbered from 1 to n according to the settings in the Cipher Filtering and Sorting fields as described below.
      Cipher Filtering and Sorting:
      These options provide the ability to sort and filter the cipher suite list.
      Cipher Filtering:
      Allows filtering the cipher list by the protocols selected in panel DMADP126 (Secure+ Create/Update Panel). Valid values are P and N. When P is specified then only cipher suites supported by the protocols selected in DMADP126 will be listed. When N is specified, DMADP126 does not influence the cipher suite selection list.
      Cipher Sorting:
      Allows the user to sort the available ciphers. If all Selection fields are blank, only unselected cipher suites are sorted. If any Selection field is non-blank then all cipher suites are sorted. The following options are available:
      SA:
      Strength Ascending (refer Understanding of Cipher Suite strength on page 796 on cipher strength)
      SD:
      Strength Descending (refer to Understanding of Cipher Suite strength on page 796 on cipher strength)
      #A
      Numeric(4-byte number for cipher) cipher name Ascending.
      #D:
      Numeric(4-byte number for cipher) cipher name Descending.
      NA:
      Alphabetic cipher name Ascending
      ND:
      Alphabetic cipher name Descending
      RSA:
      Y forces display of all RSA algorithm supported cipher suites, regardless of any other setting.
      ECDSA:
      Y forces display of all ECDSA algorithm supported cipher suites, regardless of any other setting.

      This is a scrollable panel. Use the F8 key to more forward and F7 to move back.

      CD.ZOS.USER1 (R)     Secure+ Extended Cipher Suite 0 Select 35 Filter 35 Total
      Option ===> 
      Selection:                 Sorting & Filtering
      Any       (nn ALL)         Cipher Filtering N (Protocol or None)
      TLS12     (nn ALL)         Cipher Sorting  SD (#A #D NA ND SA SD)
      TLS13     (nn ALL)         RSA              N (Y or N)
                                 ECDSA            N (Y or N)
      
         Cipher Suite                                                TLS  FI Key
      O  #    Name                                                  13 12 PS Size
      == ==== ===================================================== == == == ====
                                                                                    
      1  1302 TLS_AES_256_GCM_SHA384                                 X        256 
      2  1301 TLS_AES_128_GCM_SHA256                                 X        128 
         C02C TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384                   X  X  256 
         C024 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384                   X  X  256 
         C00A TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA                      X  X  256 
         C02B TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256                   X  X  128 
         C023 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256                   X  X  256 
         C009 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA                      X  X  128 
         C007 TLS_ECDHE_ECDSA_WITH_RC4_128_SHA                          X     128 
         C008 TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA                     X  X  168 
         C006 TLS_ECDHE_ECDSA_WITH_NULL_SHA                             X         
         C030 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384                     X  X  256 
         C028 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384                     X  X  256 
         C014 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA                        X  X  256 
         C02F TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256                     X  X  128 
         C027 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256                     X  X  128 
         C013 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA                        X  X  128 
         C011 TLS_ECDHE_RSA_WITH_RC4_128_SHA                            X     128 
         C012 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA                       X  X  168 
         C010 TLS_ECDHE_RSA_WITH_NULL_SHA                               X         
         009D TLS_RSA_WITH_AES_256_GCM_SHA384                           X  X  256 
         003D TLS_RSA_WITH_AES_256_CBC_SHA256                           X  X  256 
         0035 TLS_RSA_WITH_AES_256_CBC_SHA                              X  X  256 
         009C TLS_RSA_WITH_AES_128_GCM_SHA256                           X  X  128 
         003C TLS_RSA_WITH_AES_128_CBC_SHA256                           X  X  128 
         002F TLS_RSA_WITH_AES_128_CBC_SHA                              X  X  128 
         000A TLS_RSA_WITH_3DES_EDE_CBC_SHA                             X  X  168 
         0009 TLS_RSA_WITH_DES_CBC_SHA                                        56  
         003B TLS_RSA_WITH_NULL_SHA256                                  X         
         0006 TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5 *DEPRECATED*                 40  
         0005 TLS_RSA_WITH_RC4_128_SHA   *DEPRECATED*                   X     128 
         0004 TLS_RSA_WITH_RC4_128_MD5   *DEPRECATED*                         128 
         0003 TLS_RSA_EXPORT_WITH_RC4_40_MD5  *DEPRECATED*                    40  
         0002 TLS_RSA_WITH_NULL_SHA      *DEPRECATED*                   X         
         0001 TLS_RSA_WITH_NULL_MD5      *DEPRECATED*                             
      
      Note: DEFAULT_TO_LOCAL_NODE does not apply to the Local node record.
      Note: Select Ciphers carefully since deprecated ciphers may not be available on all systems. Check with your Security Administrator before selecting these ciphers.
      Note: The Extended Cipher Suite list will show additional information such as which ciphers support which protocols, support FIPS and the key sizes of the ciphers. For more information, see Cipher Selection Rules.
  14. Select the EA parameters option from the panel selection bar and press Enter to display the EA parameters panel.
        Secure+ Create/Update Panel            <Change Pending>                          
    Option ===>                                                                                            
                                                                                                                                      
    Node Name:   MY.REMOTE             Type:  R       (Local or Remote)                                      
     --------------------------------------------------------------------------                              
    | Security Options     |  EA Parameters        |  SSL/TLS Parameters       |                             
    | ---                     --                      ---                      |                             
     --------------------------------------------------------------------------                              
                                                                                                                                      
     Enable External Auth          N               (Yes , No , Default to Local)                           
                                                                                                                                      
     External Auth Server Def                                                                                
     External Auth Server Address                                                                            
     External Auth Server Port                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      
                                                                                                                                      
                                                               OK        Cancel                                   
                                                                 --        ---
  15. To implement the External Authentication Server application:
    1. Type N in the External Auth field to disable External Authentication Server application.
    2. Type Y in the External Auth field to enable External Authentication Server application
    3. External Auth Server Def, External Auth Server Address, and External Auth Server Port are unavailable because they are valid only for the .EASERVER remote node record.
  16. Select OK and press Enter to display the values for the local node record.
  17. Using the Save As or Save Active option displays error and warning messages. Read all warning and error messages. Continue configuring the environment without resolving warning messages, but resolve errors before you save the parameter file.
  18. After you configure the remote node record, you can save and submit the parameter file using the procedures in IBM Connect:Direct Secure Plus Operation Enablement and Validation, but if you have not added a remote node record, connections are not secure.